Skip to content
Security
Skill

/sbom-generate

Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering, and spec-version targeting. Use when asked to create an SBOM or BOM for a

BOOST
From plugin
cdxgen
1.1k14 skills
Install
$ npx -y skills add cdxgen/cdxgen --skill sbom-generate --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/sbom-generate

Context preview

The summary Claude sees to decide when to auto-load this skill.

Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering, and spec-version targeting. Use when asked to create an SBOM or BOM for a

SKILL.md

sbom-generate.SKILL.md
name: sbom-generate
description: Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering, and spec-version targeting. Use when asked to create an SBOM or BOM for a repository or directory, produce a dependency inventory, resolve licenses, or export SPDX from source.

Generate an SBOM from source

Use this skill for the common case: a user wants a CycloneDX SBOM for a repository or directory. For containers and binaries use `container-sbom`; for live hosts use `os-hardware-inventory`; to improve an SBOM that came back thin use `sbom-fidelity-loop`.

Read [reference/safety.md](../../reference/safety.md) before running anything. The dry-run-first rule and the absolute-path rule are not optional.

Core syntax

cdxgen [path] [options]

`path` defaults to `.`. Every boolean flag accepts a `--no-` prefix to invert it.

Step 1: preview

cdxgen /absolute/path/to/project --dry-run --activity-report json

Summarize what the run would read, write, execute, and fetch. Ask before the real run. Pay particular attention to whether the preview shows package-manager installs; if it does, offer `--no-install-deps` or `--lifecycle pre-build`.

Step 2: generate

cdxgen /absolute/path/to/project -o /absolute/path/to/bom.json

Auto-detection handles most projects. Reach for flags when it does not.

Choosing a project type

Omit `-t` and let cdxgen detect. Pass it when detection is wrong, when you want to constrain a large monorepo, or when the target is not source code.

# Restrict a polyglot repo to two ecosystems
cdxgen -t java -t python -o /absolute/path/to/bom.json /absolute/path/to/project

# Exclude one ecosystem instead of listing the rest
cdxgen --exclude-type mcp -o /absolute/path/to/bom.json /absolute/path/to/project

Common aliases (the full matrix is at <https://cdxgen.github.io/cdxgen/#/PROJECT_TYPES>):

| Ecosystem | Types | | ---------- | --------------------------------------------------------------------- | | Node.js | `npm`, `pnpm`, `yarn`, `bun`, `deno`, `js`, `ts`, `nodejs`, `rush` | | JVM | `java`, `kotlin`, `scala`, `groovy`, `gradle`, `maven`, `sbt`, `mill` | | Python | `python`, `uv`, `poetry`, `pdm`, `hatch`, `pixi`, `rye`, `conda` | | Go | `go`, `golang`, `gomod` | | Rust | `rust`, `cargo`, `rs` | | .NET | `csharp`, `dotnet`, `vbnet`, `fsharp` | | Ruby | `ruby`, `bundler`, `gems` | | PHP | `php`, `composer`, `wordpress` | | C/C++ | `c`, `cpp`, `conan`, `collider` | | Others | `dart`, `elixir`, `haskell`, `clojure`, `nix`, `zig`, `gleam`, `mojo` | | CI/config | `github`, `actions`, `helm` |

Pinned toolchains are supported as types too: `java21`, `python312`, `maven3.9.9`, `gradle8.14`, `ruby3.4.0`. cdxgen installs the pinned tool with sdkman and uses it instead of the project's wrapper. This is the fix when a project's wrapper is broken or targets an unsupported JDK.

Monorepos

`--recurse` defaults to `true`. For large repos this is often the wrong default:

# Single project at the root only
cdxgen --no-recurse -t java -o /absolute/path/to/bom.json /absolute/path/to/project

Combine `--no-recurse` with explicit `-t` values, or use `--exclude` to skip directories. See <https://cdxgen.github.io/cdxgen/#/MONOREPO>.

Lifecycle phases

| Phase | Behavior | | ------------ | --------------------------------------------------------------- | | `pre-build` | No package installations. Manifests and lockfiles only. | | `build` | Default. May invoke the package manager. | | `post-build` | Binaries and containers rather than source. |

cdxgen --lifecycle pre-build -o /absolute/path/to/bom.json /absolute/path/to/project

`pre-build` is the right choice for CI, containers, air-gapped hosts, and any run where modifying the project is unacceptable.

Generation profiles

`--profile` presets a bundle of flags for an intended audience.

| Profile | Intent | | -------------------- | ------------------------------------------------------- | | `generic` | Default | | `appsec` | Application-security review | | `research` | Deep security research, maximum evidence | | `operational` | Operations and runtime inventory | | `threat-modeling` | Threat-model inputs | | `license-compliance` | License resolution and compliance | | `ml` / `ml-deep` / `ml-tiny` | Machine-learning inventory at three depths | | `introspect` | Grade the scan's own fidelity and rank remediations |

cdxgen --profile license-compliance -o /absolute/path/to/bom.json /absolute/path/to/project
cdxgen --profile research --evidence -o /absolute/path/to/bom.json /absolute/path/to/project

Use `--profile introspect` when the user's real question is "why is my SBOM incomplete?" — then follow `sbom-fidelity-loop`.

Filtering the component set

| Flag | Effect | | ------------------- | ----------------------------------------------------------------- | | `--required-only` | Production/non-dev dependencies o

Read more
Ships withcdxgen

cdxgen is a CLI tool, library, REPL, and server to create, validate, sign, and verify software BOMs. It generates CycloneDX JSON BOMs and supports SPDX 3.0.1 JSON-LD export.

Get the whole plugin
Stats
1,085
Stars
263
Forks
Active
Maintenance
JavaScript
Language
Apache-2.0
License
3d ago
Last commit
6y ago
Created
3d ago
Added

Repo: cdxgen/cdxgen

Other skills on cdxgen.